
CVE-2026-42281
Proof-of-concept exploit for CVE-2026-42281, an unauthenticated SSRF in MagicMirror² ≤ 2.35.0, enabling config exfiltration, cloud metadata probing,…

Proof-of-concept exploit for CVE-2026-42281, an unauthenticated SSRF in MagicMirror² ≤ 2.35.0, enabling config exfiltration, cloud metadata probing,…

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

MAL-011: Log4J Misconfiguration Allows Malicious JavaScript in Red Hat AMQ

Multiple exploits for Monitorr

Exploit codes for rconfig <= 3.9.4

Remote vulnerability scanner for CVE-2025-24514, an ingress-nginx auth-url injection leading to NGINX config manipulation and potential RCE.…

Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the…

CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6

PoC for CVE-2026-8023: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

CVE-2024-51442 write up and example config file

based on [EQSTLab](https://github.com/EQSTLab)

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

The official exploit for rConfig 3.9.2 Post-auth Remote Code Execution CVE-2019-16663

The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

Cisco Email Security Appliance: Remote Code Execution - RCE from config file